Skip to main content

Software Security Code of Practice

For software vendors

Organisations that develop or sell software can use the Software Code of Practice to demonstrate to potential customers that their products are resilient to common cyber attacks.

This page explains how organisations ensure the development of their software (or software services) aligns with the Code, (which is available from the DSIT website).

How vendors can comply with the Software Security Code of Practice

  • 1

    Understand the Code of Practice

  • 2

    Assess requirements and plan implementation

  • 3

    Implement your solutions

    • Use your initial assessment to prioritise solutions.
    • Use the APC Self-assessment to track and document progress. 
  • 4

    Continuous improvement

    • Conduct regular audits using the APC Self-assessment to monitor compliance.
    • Update security practices based on changes in the Code and emerging threats.

We invite you to contribute to the Monitoring and Evaluation of the Software Security Code of Practice to assess the effectiveness of this policy and guide future policy decisions. Share your views as a software vendor.